Questions reporters should ask are
1) how long the website was vulnerable
2) who else accessed data
3) why it was not fixed
4) who is responsible maintaining the website
Here is a story of Australian cybersecurity researcher who reported vulnerable website to the government 2022 and it is still not fixed today
https://x.com/adamlyttleapps/status/2102958488658104365?s=20